Re: [SC-L] Provably correct microkernel (seL4)

2009-10-02 Thread Johan Peeters
sounds: this is a micro kernel and hence a security chokepoint. The other stuff running on top do not need the same level of assurance. kr, Yo -- Johan Peeters http://johanpeeters.com ___ Secure Coding mailing list (SC-L) SC-L@securecoding.org

Re: [SC-L] Provably correct microkernel (seL4)

2009-10-03 Thread Johan Peeters
gt; Secure Coding mailing list (SC-L) SC-L@securecoding.org > List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l > List charter available at - http://www.securecoding.org/list/charter.php > SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)

[SC-L] Announcement SecAppDev 2010

2010-01-04 Thread Johan Peeters
on a first-come, first-served basis. A 25% Early Bird discount is available until January 15th. Public servants receive a 50% discount. Best Wishes for 2010, Yo -- Johan Peeters Program Director http://secappdev.org ___ Secure Coding mailing list (SC-L)

[SC-L] SecAppDev 2011

2010-11-19 Thread Johan Peeters
tment. Registration is on a first-come, first-served basis. A 25% Early Bird discount is available until December 31. Public servants receive a 50% discount. Kind regards, Yo -- Johan Peeters Program Director http://secappdev.org ___ Secure Coding mailing list (SC-

[SC-L] discounts for SecAppDev for independents and start-ups

2011-01-23 Thread Johan Peeters
, but do not hesitate to contact me if you have further questions. I hope to see you soon. Yo -- Johan Peeters Program Director http://secappdev.org ___ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http

Re: [SC-L] Application Security Debt and Application Interest Rates

2011-03-06 Thread Johan Peeters
ist/charter.php > SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) > as a free, non-commercial service to the software security community. > Follow KRvW Associates on Twitter at: http://twitter.com/KRvW_Associates > _

[SC-L] security in open source components

2012-04-25 Thread Johan Peeters
? Or can anyone allay my fears? kr, Yo -- Johan Peeters http://johanpeeters.com ___ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at - http

Re: [SC-L] OWASP Podcast 95 is live!

2013-07-03 Thread Johan Peeters
C-L@securecoding.org > List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l > List charter available at - http://www.securecoding.org/list/charter.php > SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) > as a free, non-commercial servi

Re: [SC-L] OWASP Podcast 95 is live!

2013-07-03 Thread Johan Peeters
eo with a human in it, yet. Wonder if it exists > somewhere... No, it predates the time when we got a camera :-) Some of the 2013 lectures do have a human in them and are being published on the secappdev org YouTube channel. -- Johan Peeters http://secappdev.org ___

Re: [SC-L] SearchSecurity: Dynamism

2015-08-28 Thread Johan Peeters
nice one, Gary. Finally something positive about agile and DevOps. A trick that you may have missed is immutable servers, see Docker and friends. They will be a leap forward for server security when they hit the mainstream. ___ Secure Coding mailing list

[SC-L] secure application development course in Brussels

2005-01-08 Thread Johan Peeters
e calls. For further information and registration details, visit http://www.secappdev.org. -- Johan Peeters http://www.secappdev.org +32 16 649000

Re: [SC-L] Information Security Considerations for Use Case Modeling

2005-06-26 Thread Johan Peeters
ed to user stories. I have proposed to also extend user stories to abuser stories (http://www.johanpeeters.com/papers/abuser stories.pdf). kr, Yo Gunnar Peterson wrote: I have published a new paper on integrating security into Use Case Modeling: http://www.arctecgroup.net/secusecase.htm -gp

[SC-L] secure application development course

2005-12-21 Thread Johan Peeters
cations such as mail, directory services, network file systems, remote procedure calls. For further information and registration details, visit http://www.secappdev.org. -- Johan Peeters program director http://www.secappdev.org +32 16 649000 ___ Secure Codin

Re: [SC-L] Ajax one panel

2006-05-22 Thread Johan Peeters
w.com/mailman/listinfo/sc-l List charter available at - http://www.securecoding.org/list/charter.php -- Johan Peeters program director http://www.secappdev.org +32 16 649000 ___ Secure Coding mailing list (SC-L) SC-L@securecoding.org List inform

Re: [SC-L] Ajax one panel

2006-05-22 Thread Johan Peeters
y Group Direct: (703) 404-5726 Cell: (703) 727-4034 Key fingerprint = 4772 F7F3 1019 4668 62AD 94B0 AE7F http://www.cigital.com Software Confidence. Achieved. On May 21, 2006, at 8:23 AM, Johan Peeters wrote: That sounds like a very exciting idea, but I am not sure about the mechanics of gett

Re: [SC-L] Ajax one panel

2006-05-22 Thread Johan Peeters
type safety is. So the fact that javascript may (or may not) have closure fails in comparison to the fact that it is not type safe. Ajax is a disaster from a security perspective. gem -Original Message- From: Johan Peeters [mailto:[EMAIL PROTECTED] Sent: Sat May 20 15:44:46 20

Re: [SC-L] Ajax one panel

2006-05-22 Thread Johan Peeters
rgument for closure. Yay, language arcana! gem -Original Message----- From: Johan Peeters [mailto:[EMAIL PROTECTED] Sent: Sun May 21 09:08:14 2006 To: John Steven Cc: Gary McGraw; Mailing List, Secure Coding; SSG Subject:Re: [SC-L] Ajax one panel We may be at cross purposes.

Re: [SC-L] Re: Comparing Scanning Tools (false positives)

2006-06-13 Thread Johan Peeters
code, and it only produces a single false-positive for you to check out. That false positive just happens to be the complete source code listing for your entire program :) If you can guarantee it is a false positive, this is a very useful tool indeed :-) kr, Yo -- Johan Peeters progr

[SC-L] secure application development course

2006-12-21 Thread Johan Peeters
pants with a thorough grounding in application security. The course takes place in the Groot Begijnhof in Leuven, Belgium, a UNESCO World Heritage site. Registration is on a first-come, first-served basis. For more information visit the web site: http://secappdev.org. -- Johan Peeters program dir

Re: [SC-L] Darkreading: Secure Coding Certification

2007-05-12 Thread Johan Peeters
, LLC (http://www.KRvW.com) > as a free, non-commercial service to the software security community. > ___ > -- Johan Peeters http://johanpeeters.com ___ Secure Coding mailing list (SC-L) SC-L@securecoding.org Li

Re: [SC-L] Software Security Training for Developers

2007-08-19 Thread Johan Peeters
SEC(Gold) > Intel Corporation > ( (916) 377-9428 | * [EMAIL PROTECTED] > ___ > Secure Coding mailing list (SC-L) SC-L@securecoding.org > List information, subscriptions, etc - > http://krvw.com/mailman/listinfo/sc-l > List charter available at - > http://www.securecod

Re: [SC-L] Software Security Training for Developers

2007-08-20 Thread Johan Peeters
will again be 25. > - Over what period of time? > - Was it mandatory? And to Sammy's point, at what > management level was it loudly supported? > > Thanks for your insights, > Hollis > > At 11:51 AM 8/19/2007, Johan Peeters wrote: > > >From my experience with secappde

Re: [SC-L] Mainframe Security

2007-11-01 Thread Johan Peeters
sc-l > List charter available at - http://www.securecoding.org/list/charter.php > SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) > as a free, non-commercial service to the software security community. > ___ > -- J

Re: [SC-L] Mainframe Security

2007-11-02 Thread Johan Peeters
your program had to be EXACT or the mainframe would > not compile it. > > Paul Powenski > > > > > > > ljknews <[EMAIL PROTECTED]> wrote: > At 9:16 PM +0100 11/1/07, Johan Peeters wrote: > > I think this could do a great service to the community. &

[SC-L] secappdev 2008

2008-01-05 Thread Johan Peeters
y to avoid disappointment. kr, Yo -- Johan Peeters http://secappdev.org http://johanpeeters.com ___ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter av

Re: [SC-L] quick question - SXSW

2008-03-12 Thread Johan Peeters
t;> security as > >>> part of their standard operating procedures. Developers are still > >>> oftentimes lazy and sloppy, creating XSS and CSRF and SQL injection > >>> holes. > >>> > >>> I then look at SXSW from afar and think: a) shouldn't I be there > >>> evangelizing securit

[SC-L] SecAppDev 2009

2009-01-04 Thread Johan Peeters
you a safe, happy and secure 2009, Yo -- Johan Peeters Program Director http://secappdev.org ___ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at

Re: [SC-L] Some Interesting Topics arising from the SANS/CWE Top 25

2009-01-14 Thread Johan Peeters
ve to input validation. kr, Yo -- Johan Peeters http://johanpeeters.com ___ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at - http://www

Re: [SC-L] Some Interesting Topics arising from the SANS/CWE Top 25

2009-01-14 Thread Johan Peeters
quity can only be used as debt collateral, if it has a rating' :-) Before setting to work on your example, Florian, I would rephrase it as 'the date of entry of the shipment address must not be after the date of entry of credit card details'. I would then consider this an input valida